Categories /

Security - Forensic Tools (7)

DataProtectionDecryptor v1.13

Andrew Lee on 29 Nov 2023
  • 143KB (uncompressed)
  • Released on 28 Nov 2023
  • Suggested by billon

DataProtectionDecryptor allows you to decrypt passwords and other information encrypted by the DPAPI (Data Protection API) system of Windows operating system, such as passwords of Microsoft Outlook accounts, credentials files of Windows, wireless network keys, passwords in some versions of Internet Explorer, passwords and cookies of Chrome Web browser.

Category:
Runs on:WinXP / Vista / Win7 / Win8 / Win10
Writes settings to: Application folder
License: Freeware
How to extract: Download the ZIP package and extract to a folder of your choice. Launch DataProtectionDecryptor.exe.
Similar/alternative apps: EncryptedRegView
What's new?
  • Fixed bug from Version 1.12: DataProtectionDecryptor displayed extra padding bytes when decrypting DPAPI data from external drive.

pestudio standard v9.55

__philippe on 8 Nov 2023
  • 2MB (uncompressed)
  • Released on 18 Sep 2023
  • Suggested by joby_toss

pestudio shows details about applications and other system files (.exe, .dll, .cpl, .ocx, .ax, .sys etc.) without starting them including:

  • Libraries that are used by an application
  • Functions that are imported by an application
  • Functions (also anonymous) that are exported by an application
  • All functions that are forwarded to other libraries
  • Obsolete Functions that are exported and imported by an application
  • If Data Execution Prevention (DEP) Windows security mechanism is used
  • If Address Space Layout Randomization (ASLR) Windows security mechanism is used
  • If Windows security mechanism Structured Exception Handling (SEH) is used
  • Whether some sections are compressed

pestudio standard lacks some features of pro version.

Category:
Runs on:Win2K / WinXP / Vista / Win7 / Win8 / Win10
Writes settings to: Application folder
Stealth: ? Yes
Unicode support: Yes
License: Free for personal use/Liteware
How to extract: Download the ZIP package and extract to a folder of your choice. Delete AddToShell.reg and RemoveFromShell.reg. Launch pestudio.exe.
Similar/alternative apps: PPEE, PE Anatomist
What's new? See: https://www.winitor.com/tools/pestudio/changes.log
Latest comments
__philippe on 2017-11-26 21:39

All righty,... next time round,

the undersigned hereby pledge to abide by the recommendations, protocols,
procedures and regulations set forth by my Right Honourable Friend Midas,
the Member for TPFC's constituency,... cross my heart and hope to die... ;-)

__philippe

Special on 2019-09-14 18:16

Looks like with 8.98 they've removed even more features from the previous 9.87 free version (detect well-known whitelisted libraries/blacklisted resources), funny they don't mention that in the changelog.

MoisheP on 2021-08-15 03:13

v. 9.15 elicits numerous warnings.

See all

PEAnatomist 02.12224.1953

__philippe on 8 Nov 2023
  • 596KB (uncompressed)
  • Released on 24 Oct 2023
  • Suggested by billon

PEAnatomist shows almost all known data structures inside a PE file and makes some analytics.
Current version provides an entropy histogram possibly handy for cursory PE forensics

Category:
Runs on:WinXP / Vista / Win7 / Win8 / Win10
Writes settings to: Application folder
Stealth: ? Yes
Unicode support: Yes
License: MIT License
How to extract: Download the ZIP package and extract to a folder of your choice. Launch PEAnatomist.exe.
Similar/alternative apps: PPEE, MiTeC EXE Explorer, pestudio
What's new? See: https://rammerlabs.alidml.ru/changelog-eng.html
Latest comments
__philippe on 2019-12-28 12:07

PE Anatomist changelog history:

https://rammerlabs.alidml.ru/changelog-eng.html

__philippe on 2021-11-05 10:42

PEanatomist notably includes (since v0.2.4) a colorful byte-level entropy(*) histogram of the file under analysis, possibly handy for inquiring minds dabbling in PE forensics ?

* Everything you always wanted to know about entropy histograms but were scared to ask...;-)
https://crucialsecurity.wordpress.com/tag/entropy/

Add comment

PPEE v1.13.1

Special on 10 Nov 2023
  • 2MB (uncompressed)
  • Released on 10 Nov 2023
  • Suggested by billon

PPEE (Professional PE file Explorer) allows analysis of malformed and crafted PE files, making it handy for reverse-engineering, malware researchers and more. The program includes PE Export, Import, Resource, Exception, Certificate (relies on Windows API), Base Relocation, Debug, TLS, Load Config, Bound Import, IAT, Delay Import and CLR.

The program includes a HEX editor and supports Virustotal and OPSWAT's Metadefender query reports.

Category:
Runs on:WinXP / Vista / Win7 / Win8 / Win10 / Wine
Writes settings to: Application folder
Unicode support: Yes
License: Freeware
How to extract: Download the ZIP package and extract to a folder of your choice. Delete Plugin folder. Launch PPEE.exe.
Similar/alternative apps: pestudio, MiTeC EXE Explorer
What's new?
  • Now PPEE is independent of Microsoft redistributable package
  • Added Recent Files in the main PPEE menu
  • Load Config parsing improved to the newest version
  • Undecorate mangled names
  • Timestamps are human readable (relative to your local time)
  • YaraPlugin is now compatible with yara v4.3.2
  • Added Recent Files in the YaraPlugin
  • TLSH hash added in FileInfo plugin
  • Bugfixes
Latest comments
smaragdus on 2018-04-12 09:27

@doctor__philippe
What other kind of maladies do you cure? Or only software ones?

__philippe on 2018-04-12 17:50

Now that you mention it, I have been known to cure images hosting service broken links...;-)
https://www.portablefreeware.com/forums/viewtopic.php?p=89747#p89747

smaragdus on 2018-04-13 00:12

@@doctor__philippe
Thanks for the new cure!

See all

Windows File Analyzer v2.10.0

Andrew Lee on 28 Sep 2021
  • 4MB (uncompressed)
  • Released on 27 Sep 2021
  • Suggested by I am Baas

Windows File Analyzer decodes and analyzes to provide cached information for forensic analysis. Includes a tabbed interface with a multiple-document window and horizontal/vertical/cascade view settings. Analysis results can be printed in user-friendly form. The program includes a variety of analysis tools useful for seeing how much information your computer leaves behind that could represent a privacy risk or for trying to detect nefarious activity.

Features include thumbnail viewers available for Windows XP, ACDSee, Google Picasa, FastStone Viewer, and HP Digital Imaging files, displaying content with stored data and image preview. A Prefetch Analyzer looks at recent programs run and stored in the Prefetch folder while the Shortcut Analyzer for all shortcut files in specified folder and data stored in them. An Index.DAT Analyzer looks at Internet Explorer cookies, temporary files or history while a Recycle Bin decoding tool displays Info2 files that hold recycle bin content (Win2k and XP only).

A PDF-format help file is available from the author website.

Category:
Runs on:Win2K / WinXP / Vista / Win7 / Win8 / Win10
Writes settings to: None
Unicode support: Yes
License: Free for personal use
How to extract: Download the ZIP package and extract to a folder of your choice. Launch WFA.exe.
What's new?
  1. Fixed FastStone thumbnail database reading
  2. Added searchbox to FastStone analyzer
Latest comments
__philippe on 2013-07-08 20:53

Categories classification:

Currently, WindowsFileAnalyser can be looked up under 2 categories
- Files -> Miscellaneous (25)
- Security -> Privacy Tools (42)

Would it be appropriate to expand the list with the newly created "Security -> "Forensic Tools" subcategory ?

__philippe

AndTheWolf on 2021-06-18 12:36

Now at version 2.9.0 (The download link at the site is still labeled "MiTeC Windows File Analyzer 2.8.0", but the executable within the zip file shows as 2.9.0)

Add comment

JumpListsView v1.16

billon on 26 Mar 2018
  • 149KB (uncompressed)
  • Released on 25 Mar 2018
  • Suggested by Checker

JumpListsView displays the information stored by the 'Jump Lists' feature available when you right-click on something in the task bar in Windows 7 - 10. For every record found, data available includes the filename that the user opened, the date/time, the ID of the application, the size/time/attributes of the file on the time that the file was opened etc.

You can also export the Jump Lists records to csv/tab-delimited/xml/html file.

Category:
Runs on:Win7 / Win8 / Win10
Writes settings to: Application folder
Stealth: ? Yes
Unicode support: Yes
License: Freeware
How to extract: Download the ZIP package and extract to a folder of your choice. Launch JumpListsView.exe.
What's new?
  • Added 'Quick Filter' feature (View -> Use Quick Filter or Ctrl+Q). When it's turned on, you can type a string in the text-box added under the toolbar and JumpListsView will instantly filter the table, showing only items that contain the string you typed.

BinText v3.00

billon on 3 Apr 2019
  • 37KB (uncompressed)
  • Released on 12 Dec 2000
  • Suggested by __philippe

BinText is a file text scanner / extractor that helps find character strings buried in binary files. The program can extract text from any kind of file and display plain ASCII text, Unicode (double byte ANSI) text, as well as Resource strings. Additional useful information for each item is included in the "Advanced" mode. Uniquely, the program will show both the file offset and the memory offset of each string found.

Although primarily targeted for programmers, it can be used by anyone interested in ferreting out character strings buried within binary files.

Note: Although updated versions of the program exist, the 3.00 version is listed for reasons described in forums.

Category:
Runs on:Win2K / WinXP / Vista / Win7 / Win8 / Win10
Writes settings to: None
Stealth: ? Yes
Unicode support: Yes
License: Freeware
How to extract: Download the ZIP package and extract to a folder of your choice. Launch bintext.exe.
Latest comments
__philippe on 2013-07-15 08:17

Here is an old (2006) but interesting narrative about using Bintext for viewing Unicode strings in executables.

http://blog.didierstevens.com/2006/07/07/viewing-strings-in-executables/

__philippe

__philippe on 2013-07-26 18:24

BinText at your finger_tip: (WinXP tested)

Place a shortcut to Bintext in your Windows SendTo folder so that you can quickly send files to BinText by right-clicking on their names and choosing Send To -> BinText from the drop-down menu.

You can set this up by right-clicking on bintext.exe, selecting Copy then open up your WindowsSendTo folder, right click the mouse and select Paste Shortcut

As an added bonus, files get automatically loaded in BinText "Advanced view" mode, no need even for clicking the GO button...;-)

__philippe

Add comment